Multiple security vulnerabilities affecting wolfSSH versions The affected ranges vary by flaw: have been identified in wolfSSH 1.5.0 and earlier. The most critical risk is a man-in-the-middle attacker passing off a forged server key, while other flaws can lead to login poisoning, CPU exhaustion, and SFTP path crashes.
CVE-2026-16516 (CVSS 9.0 — Critical): A wolfSSH client does not validate the ECDSA host key curve identifier in a KEXDH_REPLY host key blob against the negotiated algorithm, allowing an attacker in the middle to swap in a key on a different curve that they control.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting wolfSSH versions The affected ranges vary by flaw: have been identified in wolfSSH 1.5.0 and earlier. The most critical risk is a man-in-the-middle attacker passing off a forged server key, while other flaws can lead to login poisoning, CPU exhaustion, and SFTP path crashes.
CVE-2026-16516 (CVSS 9.0 — Critical): A wolfSSH client does not validate the ECDSA host key curve identifier in a KEXDH_REPLY host key blob against the negotiated algorithm, allowing an attacker in the middle to swap in a key on a different curve that they control.[emaillocker id="1283"]
CVE-2026-83540 (CVSS 7.7 — High): A wolfSSH server does not release the Windows logon token from one connection before the next, enabling a less privileged user with a valid account to exploit this and force a login as a more privileged user.
CVE-2026-84897: A wolfSSH server accepts certain key exchange messages that only a server should send, allowing an unauthenticated client to abuse this to make the server test very large primes, burning CPU before login and confusing the server’s role in the handshake.
CVE-2026-81535: An SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check, enabling a malicious peer to open unlimited forwarding channels that the application never authorized.
CVE-2026-83742: A wstrncat unsigned integer underflow leads to an off-by-one null write in on non-Windows platforms, allowing a logged-in user to write a single null byte past a stack buffer with a crafted SFTP path, which may crash the process.
These vulnerabilities collectively present a risk of exploitation for embedded devices and IoT products using wolfSSH.
We recommend you to update wolfSSH to version 1.6.0.
The following reports contain further technical details:
[/emaillocker]